SAP Security Note
Medium priority
SAP security note 1522666, "Missing Authorization Check in SCM-APO-SCC", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functionality of SCM-APO-SCC and SCM-BAS-MD-TL to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
Implement the attached correction instruction.
Reason and prerequisites
SCM-APO-SCC and SCM-BAS-MD-TL lack permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
Affected components
- SAP_APO 30A
- SAP_APO 310
- SCM 400
- SCM 410
- SCM 500
- SCM 510
- SCM_BASIS 510
Full note on SAP: SAP Support Launchpad note 1522666
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
